CERT-FR Warns of Synology DSM Vulnerabilities
Multiple vulnerabilities in Synology DSM allow remote code execution, denial of service, and data confidentiality breaches; patches available.
CERT-FR has issued an advisory (CERTFR-2026-AVI-1209) detailing multiple vulnerabilities discovered in Synology's DiskStation Manager (DSM) operating system, which powers Synology NAS devices. The flaws affect DSM versions 7.2.1 (prior to 7.2.1-69057-12), 7.2.2 (prior to 7.2.2-72806-9), 7.3 (prior to 7.3.2-86009-4), and 7.4.x (prior to 7.4-90075). Eight CVEs are referenced: CVE-2026-13623, CVE-2026-13635, CVE-2026-13639, CVE-2026-13666, CVE-2026-13673, CVE-2026-13683, CVE-2026-13684, and CVE-2026-6205.
The vulnerabilities collectively enable a range of impacts including remote arbitrary code execution, remote denial of service, data confidentiality breaches, data integrity compromise, security policy bypass, indirect remote code injection (XSS), and SQL injection. No specific exploitation-in-the-wild has been reported by CERT-FR; the advisory is a standard vulnerability disclosure sourced from Synology's own security bulletin (Synology_SA_26_13, published 18 September 2026).
Defenders operating Synology NAS devices should prioritize patching to the fixed DSM versions referenced above. Given the exposure of NAS devices to remote networks and the potential for remote code execution, organizations should verify DSM version compliance and apply Synology's official patches promptly, particularly for internet-facing storage systems.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1209
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free